SB20260919151 - Off-by-one in Linux kernel soc



SB20260919151 - Off-by-one in Linux kernel soc

Published: September 19, 2026

Security Bulletin ID SB20260919151
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Off-by-one (CVE-ID: CVE-2026-90068)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read memory out of bounds.

The vulnerability exists due to an off-by-one error in snd_soc_dapm_put_enum_double() when writing a second enum channel value. A local user can set the second enum channel value equal to the number of enum items to read one element past the end of the value table.

The affected adav80x control reports two values, and core input validation is disabled by default.


Remediation

Install update from vendor's website.